Privacy Policy
Last Updated: September 16, 2026
1. Data Collection & Security
We never store anything that identifies you. When you paste your JSON/API data into our analyzer, it is processed in real time to generate your insight and your raw filing is not kept. By default we retain only de-identified case milestones — status codes and dates, your form type, and your service center — to power the community timeline benchmarks everyone relies on. Your receipt number is stored only as a one-way cryptographic hash, and sensitive identifiers — your Alien Registration Number (A-Number), applicant name, and mailing address — are never written to our database. You can opt out and delete your contribution at any time (see Section 4).
Saved analyses — so you can return to your results. When you purchase an analysis, we save the analysis we generate for you (not your raw filing) so you can reopen your results later without re-pasting everything — for example, from the link in your receipt email. This saved copy is tied to your purchase, retrievable only through a private, non-guessable link, automatically deleted after 90 days, and you can delete it yourself at any time from the results screen (or by contacting us). We minimize what it contains and never include your A-Number or applicant name.
Your case ID (e.g., IOE...) is used to generate the official USCIS API links for your convenience and, if you purchased an analysis, to label the saved copy so you can recognize it.
2. Account & Subscription Data
If you subscribe to our monthly plan or make a one-time purchase, we store only the following account information to manage your subscription:
- Email address — used to identify your account and check subscription status.
- Subscription status — whether your plan is active, canceled, or past due.
- Stripe customer ID and subscription ID — used to link your account to Stripe for billing management.
We never store your credit card details. All payment information is handled securely by Stripe. Aside from the saved analysis described in Section 1 — which you can delete at any time — your billing data and your case data are kept separate.
3. Local Storage & Cookies
We use strictly necessary cookies and local browser storage to provide core site functionality, maintain security, and prevent the abuse of promotional offers.
To improve your experience, we use your browser's Local Storage to remember your email for subscription status checks and to prevent repeated promotional discount popups once claimed. Analysis results may be temporarily stored in Session Storage on your device during your visit. This data stays on your computer and is never uploaded to us.
We also use Google Analytics and Google Tag Manager (cookies) to track anonymous usage statistics (e.g., page views) to help us improve the website.
4. Community Milestone Data & Cryptographic Anonymization
To help the broader immigration community benchmark realistic USCIS processing timelines, CaseStatusAPI contributes de-identified case milestones by default. This data carries no information that identifies you or your case, and you can opt out and delete your contribution at any time.
- On by Default, Anonymized — Opt Out Anytime: De-identified milestones are contributed automatically so every applicant benefits from the shared benchmark. Because the data carries nothing that identifies you, it is not personal data — and you can opt out, and delete what was contributed, at any time.
- Cryptographic SHA-256 Hashing: When contributing, your raw receipt number (e.g., IOE...) is permanently converted into a one-way cryptographic SHA-256 hash. We never store or database readable receipt numbers.
- Zero Personal Identifiers (PII): We strictly strip and discard all applicant names, Alien Registration Numbers (A-Numbers), birth dates, postal addresses, phone numbers, and payment information.
- Milestone-Only Telemetry: Only high-level timeline metadata (Form type, Service Center/Field Office, and milestone transition timestamps) is collected to compute community velocity metrics.
- Revocation & Deletion: You can opt out at any time through the community tracker settings.
5. Third-Party Services
Stripe: We use Stripe for payment and subscription processing. Your payment information is handled entirely by Stripe securely; we never see or store your credit card details. See Stripe's Privacy Policy.
OpenAI: We use OpenAI's API to generate the case insights. Data sent to OpenAI is subject to their strict enterprise privacy policies and is not used to train their models.
Supabase: We use Supabase to securely store your account and subscription information (email, subscription status). The only case data stored is de-identified milestones (no name, A-Number, or address); nothing that identifies you or links a case back to a person is ever stored.
Microsoft Clarity: We use Microsoft Clarity to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. By using our site, you agree that we and Microsoft can collect and use this data. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.
6. Data Retention
Your subscription account data is retained as long as your account is active. If you cancel, we may keep a minimal record so you can reactivate later. We keep account data only as long as it is needed for the purposes described in this policy, and we remove or de-identify it when it is no longer needed. You can delete your account and its data yourself at any time from your Account page, or by emailing info@casestatusapi.com. Self-service deletion is immediate; email requests are completed within 30 days.
Saved analyses are automatically deleted 90 days after they are created. You can delete a saved analysis immediately from the results screen, or, when signed in, delete all saved analyses tied to your account. Optional community milestone data (Section 4) is anonymized and retained to compute aggregate trends; you can opt out at any time.
7. Categories of Data We Collect (and What We Never Collect)
We practice data minimization and collect only what the service needs:
- Account data: your email address and your subscription or purchase status.
- Billing data: a Stripe customer and subscription ID. We never see or store your card number.
- De-identified case milestones: your form type, service center, event codes, and status dates, plus a one-way salted hash of your receipt number. This carries nothing that identifies you.
- Website usage data: anonymous analytics and product-improvement metrics, including page views and interaction data such as heatmaps and session replay, through Google Analytics and Microsoft Clarity.
We do not collect, and we ask you never to submit, the following:
- Precise geolocation data.
- Financial account information, such as bank or card numbers.
- Medical, health, or biometric information.
- Your device contacts, call logs, or messages.
- Your Alien Registration Number (A-Number), full name, date of birth, phone number, or mailing address. If any of these appear in data you paste, they are stripped and never written to our database.
8. How We Share Your Data, and Your Choices
We do not sell your personal information. We have never sold it, and we do not share it for money, for advertising, or for any other company's independent use.
We share data only with the service providers that make the product work — the same providers named in Section 5 — and only so they can perform that work for us. These providers are bound by contract to protect your data, to use it only to provide their service to us, and not to disclose it or use it for their own purposes. We do not permit any third party to use or disclose your information — including de-identified, anonymized, or pseudonymized data — for any reason without your consent, except where the law requires it.
Your choices. Contributing de-identified community milestones (Section 4) is your choice. The first time you use the analyzer we ask you directly, with a clear yes-or-no prompt, and you can change your answer at any time from your Account or the Insights page. Turning it off deletes what was contributed. The benefit of contributing is more accurate community processing-time benchmarks for everyone. Because the contribution is de-identified — no name, A-Number, or readable receipt number — the risk to you is minimal. We do not collect genetic, family-history, or relatives' information, so sharing your milestones cannot reveal anything about other people.
9. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use it, to access a copy of it, to ask us to correct or delete it, and to opt out of its sale or sharing. Because we do not sell or share your personal information, there is nothing for you to opt out of. We will never treat you differently for exercising these rights.
Do Not Sell or Share My Personal Information: we do not sell or share your personal information. To make any privacy request, email info@casestatusapi.com. We will respond within the time the law allows, generally 45 days.
10. Data Breach Notification
If we discover a data breach that affects your personal information, we will notify you without undue delay, consistent with applicable law. Our notice will explain what happened, what information was involved, and the steps you can take to protect yourself.
11. Closing Your Account
You can close your account at any time. From your Account page, the "Delete account" control removes your account and its data immediately and cancels any active subscription for you. You can also email info@casestatusapi.com to request deletion, which we complete within 30 days.
12. Business Transfers & Change of Ownership
If our business is sold, merged, or transferred, we will require the new owner to honor a privacy policy at least as protective as this one. We will notify you of any change of ownership before your data becomes subject to a different policy, and you may delete or export your data before the transfer takes effect.
13. Changes to This Policy
If we make a material change to this policy or to how we handle your data, we will not apply it silently. We will notify you, give you a plain-language summary of what changed, and ask for your active consent before the change takes effect for your account. Minor, non-material edits are reflected by updating the "Last Updated" date at the top of this page.
14. Contact Us
If you have any questions about this Privacy Policy or wish to request deletion of your data, please contact us at info@casestatusapi.com.
Operated by ComplyWhiz LLC.